Digital shields failing against infostealers and critical infrastructure attacks.

Daily Cybersecurity News - May 9, 2026

Linux Dirty Frag Chain Roots Systems

Linux kernel just shipped another local root pipe weeks after Copy Fail. Attackers chain page cache writes to escalate from unprivileged user to root.

Dubbed Dirty Frag, CVE-2026-43284 and CVE-2026-43500 deliver 4-byte store primitives via xfrm-ESP and RxRPC sockets. CVSS 7.8. A public single-command PoC exploit is already available on GitHub.

Hits kernels since 2017 across Ubuntu 24.04, RHEL 10, Fedora 44, AlmaLinux 10, openSUSE, CentOS Stream 10. Works even with Copy Fail mitigations.

Single-command exploit published May 8, 2026.

Source: Tenable Blog

Fake OpenAI Repo Tops Hugging Face With Infostealer

Crooks posted a fake OpenAI repository on Hugging Face that hit the trending list to push infostealer malware at Windows users.

They typosquatted OpenAI's Privacy Filter project as Open-OSS/privacy-filter. A loader.py script pulls a JSON payload and runs PowerShell to drop sefirah, a Rust infostealer that grabs browser creds, crypto wallets, and screenshots.

Typosquatting repos is standard supply chain stuff, but the Rust stealer with VM/sandbox evasion adds a fresh twist. Overlaps with a recent npm campaign pushing WinOS 4.0 implant.

Repo racked up 244,000 downloads and 667 fake likes before takedown.

Russian Hackers Breach Polish Water Plants, US Warned

Russian hackers breached five Polish water treatment plants, gaining control over industrial systems that could poison supplies.

Poland's ABW detected the intrusions in 2025 across towns like Jabłonna Lacka and Szczytno. Attackers accessed ICS to alter device parameters, risking water supply disruptions or contamination. They also targeted power grids and military sites.

Tactics mirror prior sabotage in Ukraine and US incidents like Oldsmar. No novel tricks here, just persistent hybrid warfare against NATO infrastructure.

APT28 and APT29 named in the ABW report, alongside Belarusian UNC1151.

Source: TechCrunch